FAQ   Search   Register   Login

CIOL Network sites



Post new topic Reply to topic  [ 3 posts ] 
Author Message
 Post subject: Klez Worm Attack
PostPosted: Thu Jul 15, 2010 2:14 pm 
Offline
Veteran

Joined: Sun Apr 05, 2009 6:47 pm
Posts: 43
For the past 2 days I seem to have been infected/attacked by the W32 Klez-H Virus/ worm., which disables me to access my eMail web clients, esp. http://www.gmail.com (gets redirected). The History list shows my http://www.gmail.com page access with the following within quotes:

" Gmail.com | W32 Klez-H | Gmail Registration | Klez-Worm | Linux Email Server- "

What is the solution/ procedure to clean this up ? What is the typical behavior of this Virus attack/ worm.


Report this post
Top
 Profile  
Reply with quote  
 Post subject: Re: Klez Worm Attack
PostPosted: Mon Jul 19, 2010 12:50 am 
Offline
Grand Master

Joined: Fri Mar 19, 2004 2:50 pm
Posts: 1646
Location: Cyberspace
Change your password,security question,secondary email-id and all the account details as soon as possible.
https://www.google.com/accounts/EditPasswd?hl=en-US

Immediately change your password and security question ( also change your secondary id and mobile number if they too got changed. ) :
https://www.google.com/accounts/ManageAccount
then clear your browser's cookie and cache.

If your account has been compromised/hacked/stolen you will need to check at least all of the following things:
Account Security:
Settings -> Accounts and Import -> Google Account Settings -> Change Password [pick a new secure password]
Settings -> Accounts and Import -> Google Account Settings -> Change Password Recovery Options [verify secret question, SMS and secondary e-mail address]
Potential Spam:
Settings -> General -> Signature [make sure nothing as been added]
Settings -> General -> Vacation Responder [make sure it's disabled and empty]
E-mail Theft
Settings -> Accounts and Import -> Send Mail As [make sure it is using your correct e-mail address]
Settings -> Filters [no filters that forward or delete e-mail]
Settings -> Forwarding and POP/IMAP -> Forwarding [disabled or correct address]
Settings -> Forwarding and POP/IMAP -> POP Download [disabled]
Settings -> Forwarding and POP/IMAP -> IMAP Access [disabled]

_________________
"Thou shalt not follow the null pointer for at it's end madness and chaos lies."


Report this post
Top
 Profile  
Reply with quote  
 Post subject: Re: Klez Worm Attack
PostPosted: Mon Jul 19, 2010 12:51 am 
Offline
Grand Master

Joined: Fri Mar 19, 2004 2:50 pm
Posts: 1646
Location: Cyberspace
n Gmail you have the option to check what is the IP from where the account is being accessed.
At the bottom of the Inbox page ...
E.g

You are currently using x70MB (1x%) of your xxxx MB.
Last account activity: 1 hour ago at this IP (xxx.xxx.xxx.xxx). Details

Where xxx are values for storage amount and IP address.
Click on Details

A new popup window will come up ..

Activity on this account
This feature provides information about the last activity on this mail account and any concurrent activity. Learn more

This account does not seem to be open in any other location.
If you see that the account is logged in from somewhere else .. logout
(this could be a genuine case if you also login via mobile.. blackberry etc)


Recent activity:
Access Type [ ? ]
(Browser, mobile, POP3, etc.) IP address [ ? ] Date/Time
(Displayed in your time zone)
Browser * xxx.xxx.xxx.xxx 01:48 (0 minutes ago)
Browser xxx.xxx.xxx.xxx 00:30 (1 hour ago)
Browser xxx.xxx.xxx.xxx 00:15 (1.5 hours ago)
Browser xxx.xxx.xxx.xxx 23:57 (1.5 hours ago)
Browser xxx.xxx.xxx.xxx 23:45 (2 hours ago)
* indicates activity from the current session.
This computer is using IP address xxx.xxx.xxx.xxx

_________________
"Thou shalt not follow the null pointer for at it's end madness and chaos lies."


Report this post
Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 5:30 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group